Pc infecté virus bagle rapport findykill

pascal21850 Messages postés 5 Statut Membre -  
jlpjlp Messages postés 52399 Statut Contributeur sécurité -
Bonjour, le forum
je viens vers vous pour essayer avec votre aide de débarrasser mon pc des bagles qui ont infectés mon pc
je vous joint un rapport findykill
en matière de sécurirté pc je n'y connais pas grand chose, je vous demanderais d'être indulgent
merci

----------------- FindyKill V4.711 ------------------

* User : Pascal C - PASCAL
* Emplacement : C:\Program Files\FindyKill
* Outils Mis a jours le 05/01/09 par Chiquitine29
* Recherche effectuée à 21:21:24 le 12/01/2009
* Windows XP - Internet Explorer 7.0.5730.13

((((((((((((((((( *** Recherche *** ))))))))))))))))))

--------------- [ Processus actifs ] ----------------

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Quick GPS Connection Data Download Manager\DesktopLtoManager.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe
C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADE.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe
C:\Documents and Settings\Pascal C\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\ConquerCam\ConquerCam.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Documents and Settings\Pascal C\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Pascal C\Application Data\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\PC Tools Firewall Plus\FWService.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\eMule\emule.exe
C:\Documents and Settings\Pascal C\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Pascal C\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
C:\Documents and Settings\Pascal C\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\CCleaner\CCleaner.exe

--------------- [ Fichiers/Dossiers infectieux ] ----------------

»»»» Presence des fichiers dans C:

»»»» Presence des fichiers dans C:\WINDOWS

»»»» Presence des fichiers dans C:\WINDOWS\Prefetch

»»»» Presence des fichiers dans C:\WINDOWS\system32

»»»» Presence des fichiers dans C:\WINDOWS\system32\drivers

»»»» Presence des fichiers dans C:\Documents and Settings\Pascal C\Application Data

»»»» Presence des fichiers dans C:\DOCUME~1\PASCAL~1\LOCALS~1\Temp

»»»» Presence des fichiers dans C:\Documents and Settings\Pascal C\Local Settings\Temporary Internet Files\Content.IE5

Found ! [06/12/2004 16:48] - C:\Program Files\EPSON\Creativity Suite\File Manager1\Readme\_fr\ReadMe.txt

--------------- [ Registre / Startup ] ----------------

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
H/PC Connection Agent="C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
EPSON Stylus DX4800 Series=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADE.EXE /P26 "EPSON Stylus DX4800 Series" /M "Stylus DX4800" /EF "HKCU"
ctfmon.exe=C:\WINDOWS\system32\ctfmon.exe
BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}="C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe"
Google Update="C:\Documents and Settings\Pascal C\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
Skype="C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
WMPNSCFG=C:\Program Files\Windows Media Player\WMPNSCFG.exe
wLite="C:\Program Files\wLite\wLite.exe" -auto
ConquerCam=C:\Program Files\ConquerCam\ConquerCam.exe /tray

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
Sunkist2k=C:\Program Files\Multimedia Card Reader\shwicon2k.exe
NeroFilterCheck=C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
NBKeyScan="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
VTPreset=VTPreset.exe
NvCplDaemon=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
nwiz=nwiz.exe /install
NvMediaCenter=RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
SunJavaUpdateSched="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
Lto Manager="C:\Program Files\Quick GPS Connection Data Download Manager\DesktopLtoManager.exe"
avgnt="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
00PCTFW="C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" -s
LogitechCommunicationsManager="C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
LogitechQuickCamRibbon="C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
<NO NAME>=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL=
Installed=1
<NO NAME>=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI=
NoChange=1
Installed=1
<NO NAME>=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS=
Installed=1
<NO NAME>=

--------------- [ Registre / Clés infectieuses ] ----------------

--------------- [ Etat / Services ] ----------------

+- Services : [ Auto=2 / Demande=3 / Désactivé=4 ]

Ndisuio - Type de démarrage = 3

EapHost - Type de démarrage = 2

Ip6Fw - Type de démarrage = 2

SharedAccess - Type de démarrage = 2

wuauserv - Type de démarrage = 2

wscsvc - Type de démarrage = 2

--------------- [ Recherche dans supports amovibles] ----------------

+- Informations :

C: - Lecteur fixe

D: - Lecteur fixe

I: - Lecteur fixe

+- presence des fichiers :

--------------- [ Registre / Mountpoint2 ] ----------------

-> Not found !

------------------- ! Fin du rapport ! --------------------
bonne nuit
A voir également:

7 réponses

jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 040
 
slt

antivir marche? colle un rapport avec

puis

Télécharge ici :

http://images.malwareremoval.com/random/RSIT.exe

random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.

Double-clique sur RSIT.exe afin de lancer RSIT.

Clique Continue à l'écran Disclaimer.

Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

Poste le contenu de log.txt (<<qui sera affiché)
ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

NB : Les rapports sont sauvegardés dans le dossier C:\rsit
0
ghost-vistasuk Messages postés 507 Statut Membre 115
 
as-tu déja un antivirus? sinon essaie celui la tu peux toujours deinstaller le tien

http://www.commentcamarche.net/telecharger/telechargement 55 antivir
0
pascal21850 Messages postés 5 Statut Membre
 
bonjour voila ce qui est demandé
merci pour votre aide
Logfile of random's system information tool 1.05 (written by random/random)
Run by Pascal C at 2009-01-13 06:52:55
Microsoft Windows XP Édition familiale Service Pack 3
System drive C: has 98 GB (64%) free of 153 GB
Total RAM: 1535 MB (60% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:48:52, on 09/12/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\Program Files\TomTom HOME\TomTomHOME.exe
C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Quick GPS Connection Data Download Manager\DesktopLtoManager.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADE.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Documents and Settings\Pascal C\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\PC Tools Firewall Plus\FWService.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft ActiveSync\WCESMgr.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Documents and Settings\Pascal C\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Pascal C\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Pascal C\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Pascal C\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ww17.ads.eorezo.com/cgi-bin/advert/getads.cgi?x_format=redirect&x_dp_id=9
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ww17.ads.eorezo.com/cgi-bin/advert/getads.cgi?x_format=redirect&x_dp_id=9
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F3 - REG:win.ini: run= 
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: TBBho Class - {F8EA6827-1B82-494a-ACAC-A582A714DCA8} - C:\WINDOWS\sbsHOHo.dll
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME\TomTomHOME.exe" -s
O4 - HKLM\..\Run: [00PCTFW] "C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" -s
O4 - HKLM\..\Run: [VTPreset] VTPreset.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Lto Manager] "C:\Program Files\Quick GPS Connection Data Download Manager\DesktopLtoManager.exe"
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [EPSON Stylus DX4800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADE.EXE /P26 "EPSON Stylus DX4800 Series" /M "Stylus DX4800" /EF "HKCU"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Pascal C\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [WeatherWatcherLive] "C:\Program Files\Weather Watcher Live\ww.exe"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5036.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Firewall Plus (PCToolsFirewallPlus) - PC Tools - C:\Program Files\PC Tools Firewall Plus\FWService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XII.SP1\Win32\RpcDataSrv.exe
O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XII.SP1\RpcSandraSrv.exe

--
End of file - 9654 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3997960634-2553511711-1556241692-1007.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64F56FC1-1272-44CD-BA6E-39723696E350}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll [2008-12-04 92504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2008-11-18 408952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a8f9752d-e2b8-4e7a-86b5-499f4330e2fe}]
Eazel-FR Toolbar - C:\Program Files\Eazel-FR\tbEaze.dll [2008-11-23 1784856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2008-12-08 1067352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2008-12-08 1067352]
{a8f9752d-e2b8-4e7a-86b5-499f4330e2fe} - Eazel-FR Toolbar - C:\Program Files\Eazel-FR\tbEaze.dll [2008-11-23 1784856]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Sunkist2k"=C:\Program Files\Multimedia Card Reader\shwicon2k.exe [2005-02-25 131072]
"NeroFilterCheck"=C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe [2007-03-01 153136]
"NBKeyScan"=C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [2007-09-20 1836328]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
"VTPreset"=C:\WINDOWS\system32\VTPreset.exe [2004-02-24 45056]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-10-07 13574144]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2008-10-07 86016]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
"Lto Manager"=C:\Program Files\Quick GPS Connection Data Download Manager\DesktopLtoManager.exe [2005-06-29 53248]
"avgnt"=C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe [2008-06-12 266497]
"00PCTFW"=C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe [2008-12-11 2652056]
"LogitechCommunicationsManager"=C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe [2007-10-25 563984]
"LogitechQuickCamRibbon"=C:\Program Files\Logitech\QuickCam\Quickcam.exe [2007-10-25 2178832]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"=C:\Program Files\Microsoft ActiveSync\wcescomm.exe [2006-11-13 1289000]
"EPSON Stylus DX4800 Series"=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADE.EXE [2005-02-02 98304]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe [2007-09-20 202024]
"Google Update"=C:\Documents and Settings\Pascal C\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-06 133104]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2008-11-18 21633320]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2006-11-03 204288]
"wLite"=C:\Program Files\wLite\wLite.exe -auto []
"ConquerCam"=C:\Program Files\ConquerCam\ConquerCam.exe [2003-03-09 3452928]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"gi170593714"=C:\DOCUME~1\PASCAL~1\LOCALS~1\Temp\36V4PMAT\implus_5_42_ppc\Resume.exe C:\Documents and Settings\Pascal C\Mes documents\implus_5_42_ppc.exe /resume:C:\DOCUME~1\PASCAL~1\LOCALS~1\Temp\36V4PMAT Please insert a first setup disk or map network drive with file C:\Documents and Settings\Pascal C\Mes documents\implus_5_42_ppc.exe IMPlus 3.0 Installation []

C:\Documents and Settings\Pascal C\Menu Démarrer\Programmes\Démarrage
Outil de notification Live Search.lnk - C:\Documents and Settings\Pascal C\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NBF]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nbf.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ProtectedStorage]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vds]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\SiSoftware\SiSoftware Sandra Lite XII.SP1\Win32\RpcDataSrv.exe"="C:\Program Files\SiSoftware\SiSoftware Sandra Lite XII.SP1\Win32\RpcDataSrv.exe:*:Enabled:SiSoftware Database Agent Service"
"C:\Program Files\SiSoftware\SiSoftware Sandra Lite XII.SP1\RpcSandraSrv.exe"="C:\Program Files\SiSoftware\SiSoftware Sandra Lite XII.SP1\RpcSandraSrv.exe:*:Enabled:SiSoftware Sandra Agent Service"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\Program Files\eMule\emule.exe"="C:\Program Files\eMule\emule.exe:*:Enabled:eMule"
"C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\wLite\wLite.exe"="C:\Program Files\wLite\wLite.exe:*:Enabled:webcamXP"
"C:\Program Files\ConquerCam\ConquerCam.exe"="C:\Program Files\ConquerCam\ConquerCam.exe:*:Enabled:ConquerCam"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ee5aa206-7aa4-11dd-bc4c-0013d3a9fa58}]
shell\AutoRun\command - M:\InstallTomTomHOME.exe


======List of files/folders created in the last 1 months======

2009-01-13 06:52:55 ----D---- C:\rsit
2009-01-12 07:13:52 ----A---- C:\WINDOWS\system32\NSBAddscript.dll
2009-01-12 07:13:52 ----A---- C:\WINDOWS\system32\cmax40.dll
2009-01-12 07:13:49 ----A---- C:\WINDOWS\system32\TLBINF32.DLL
2009-01-12 07:13:49 ----A---- C:\WINDOWS\system32\mscetreeview.dll
2009-01-12 07:13:49 ----A---- C:\WINDOWS\system32\mscetabstrip.dll
2009-01-12 07:13:49 ----A---- C:\WINDOWS\system32\mscepicture.dll
2009-01-12 07:13:49 ----A---- C:\WINDOWS\system32\mscelistview.dll
2009-01-12 07:13:49 ----A---- C:\WINDOWS\system32\msceimagelist.dll
2009-01-12 07:13:49 ----A---- C:\WINDOWS\system32\finance.dll
2009-01-12 07:13:49 ----A---- C:\WINDOWS\system32\ExMenu.dll
2009-01-12 07:13:49 ----A---- C:\WINDOWS\system32\adocedt31.dll
2009-01-12 07:13:48 ----A---- C:\WINDOWS\system32\mscewinsock.dll
2009-01-12 07:13:48 ----A---- C:\WINDOWS\system32\msceimage.dll
2009-01-12 07:13:48 ----A---- C:\WINDOWS\system32\MSCEGRID.DLL
2009-01-12 07:13:48 ----A---- C:\WINDOWS\system32\MSCEFILE.DLL
2009-01-12 07:13:48 ----A---- C:\WINDOWS\system32\MSCECOMM.DLL
2009-01-12 07:13:48 ----A---- C:\WINDOWS\system32\mscecomdlg.dll
2009-01-12 07:13:47 ----A---- C:\WINDOWS\system32\NSBPictB.dll
2009-01-12 07:13:47 ----A---- C:\WINDOWS\system32\ExPropertiesList.dll
2009-01-12 07:13:47 ----A---- C:\WINDOWS\system32\CMDLGD6.dll
2009-01-12 07:13:46 ----D---- C:\Program Files\NSBasic
2009-01-10 19:36:41 ----D---- C:\Program Files\SBSH Calendar Touch
2009-01-10 17:50:21 ----D---- C:\WINDOWS\TEMP
2009-01-10 13:38:21 ----D---- C:\Program Files\Paragon Software (MCD)
2009-01-10 10:49:00 ----D---- C:\Program Files\FindyKill
2009-01-09 20:36:03 ----D---- C:\Program Files\ConquerCam
2009-01-09 20:27:14 ----RA---- C:\WINDOWS\system32\JpegCode.dll
2009-01-09 20:27:14 ----RA---- C:\WINDOWS\system32\CoachDlg.dll
2009-01-09 20:21:13 ----RA---- C:\WINDOWS\system32\CoachWia.dll
2009-01-09 20:21:12 ----RA---- C:\WINDOWS\system32\CoachWrp.dll
2009-01-09 20:13:56 ----D---- C:\Program Files\REAL Software
2009-01-09 20:13:56 ----D---- C:\Documents and Settings\Pascal C\Application Data\REALbasic 2006
2009-01-09 20:13:50 ----D---- C:\Program Files\Eazel-FR
2009-01-09 20:13:43 ----D---- C:\Program Files\Fichiers communs\Wise Installation Wizard
2009-01-09 20:13:43 ----D---- C:\Config.Msi
2009-01-09 20:13:36 ----D---- C:\Program Files\IM+ 5.42 for PocketPC
2009-01-09 20:13:36 ----D---- C:\Program Files\EoRezo
2009-01-09 20:13:36 ----D---- C:\Program Files\CamStudio(2)
2009-01-09 20:13:35 ----D---- C:\Program Files\AskTBar
2009-01-09 20:13:35 ----D---- C:\PocketTiME
2009-01-09 20:13:35 ----D---- C:\lgupload
2009-01-09 20:12:57 ----D---- C:\Documents and Settings\All Users\Application Data\Avira
2009-01-09 18:56:32 ----D---- C:\Documents and Settings\All Users\Application Data\Avira(2)
2009-01-09 18:47:41 ----D---- C:\Program Files\The Cleaner Demo
2009-01-09 12:31:20 ----D---- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2009-01-09 09:38:45 ----D---- C:\Documents and Settings\Pascal C\Application Data\ArcSoft
2009-01-09 09:37:46 ----D---- C:\Program Files\ArcSoft
2009-01-09 07:56:18 ----D---- C:\Program Files\Imaveo
2009-01-08 20:24:03 ----D---- C:\Documents and Settings\All Users\Application Data\Logishrd
2009-01-08 20:23:59 ----D---- C:\Program Files\Fichiers communs\LogiShrd
2009-01-08 20:23:57 ----D---- C:\Documents and Settings\All Users\Application Data\Logitech
2009-01-08 20:23:56 ----D---- C:\Program Files\Logitech
2009-01-08 20:07:59 ----A---- C:\WINDOWS\OverlayXP.ini
2009-01-08 20:03:43 ----D---- C:\Documents and Settings\All Users\Application Data\webcamXP5
2009-01-08 13:31:22 ----D---- C:\Program Files\Fichiers communs\PC Tools
2009-01-08 12:09:13 ----SHD---- C:\RECYCLER
2009-01-08 12:05:56 ----D---- C:\Program Files\Avira
2009-01-08 11:56:59 ----A---- C:\ComboFix.txt
2009-01-08 11:44:51 ----A---- C:\Boot.bak
2009-01-08 11:44:47 ----RASHD---- C:\cmdcons
2009-01-08 11:38:25 ----A---- C:\WINDOWS\zip.exe
2009-01-08 11:38:25 ----A---- C:\WINDOWS\VFIND.exe
2009-01-08 11:38:25 ----A---- C:\WINDOWS\SWXCACLS.exe
2009-01-08 11:38:25 ----A---- C:\WINDOWS\SWSC.exe
2009-01-08 11:38:25 ----A---- C:\WINDOWS\SWREG.exe
2009-01-08 11:38:25 ----A---- C:\WINDOWS\sed.exe
2009-01-08 11:38:25 ----A---- C:\WINDOWS\NIRCMD.exe
2009-01-08 11:38:25 ----A---- C:\WINDOWS\grep.exe
2009-01-08 11:38:25 ----A---- C:\WINDOWS\fdsv.exe
2009-01-08 11:38:12 ----D---- C:\Qoobox
2009-01-08 11:05:36 ----A---- C:\Rooter.txt
2009-01-08 11:04:57 ----D---- C:\Rooter$
2009-01-08 09:12:00 ----A---- C:\WINDOWS\system32\OVUI2RC.dll
2009-01-08 09:12:00 ----A---- C:\WINDOWS\system32\OVUI2.dll
2009-01-08 09:12:00 ----A---- C:\WINDOWS\system32\OVComS.exe
2009-01-08 09:12:00 ----A---- C:\WINDOWS\system32\OVComC.dll
2009-01-08 09:12:00 ----A---- C:\WINDOWS\system32\OVCodec2.dll
2009-01-05 19:06:49 ----D---- C:\Program Files\Microsoft SDKs
2009-01-05 12:41:22 ----D---- C:\Program Files\SBSH PhoneWeaver
2009-01-04 20:56:43 ----D---- C:\WINDOWS\Agenda One
2009-01-03 13:56:23 ----D---- C:\Games
2009-01-03 12:52:50 ----D---- C:\Program Files\pocketGEAR
2009-01-01 18:25:16 ----D---- C:\Program Files\Microsoft.NET
2009-01-01 09:50:59 ----D---- C:\Program Files\RegCleaner
2008-12-31 14:23:42 ----A---- C:\libSRTP_log.txt
2008-12-31 14:21:30 ----D---- C:\Program Files\CounterPath
2008-12-18 17:43:30 ----D---- C:\Program Files\Microsoft Silverlight
2008-12-18 17:41:49 ----D---- C:\Program Files\Microsoft Sync Framework
2008-12-18 17:37:06 ----D---- C:\Program Files\Microsoft
2008-12-18 17:36:34 ----D---- C:\Program Files\Windows Live SkyDrive
2008-12-18 17:23:51 ----D---- C:\Program Files\Fichiers communs\Windows Live
2008-12-16 20:29:52 ----A---- C:\WINDOWS\system32\glide2x.dll
2008-12-16 20:29:40 ----A---- C:\WINDOWS\uninst.exe
2008-12-16 20:02:28 ----A---- C:\WINDOWS\system32\iyvu9_32.dll
2008-12-16 16:27:00 ----D---- C:\Program Files\City Interactive
2008-12-16 16:06:22 ----A---- C:\WINDOWS\system32\CmdLineExt.dll
2008-12-16 16:05:27 ----D---- C:\Program Files\GameShadow
2008-12-16 15:58:53 ----D---- C:\Program Files\Eidos
2008-12-16 11:00:08 ----D---- C:\Documents and Settings\Pascal C\Application Data\skypePM
2008-12-16 10:58:16 ----D---- C:\Documents and Settings\Pascal C\Application Data\Skype
2008-12-16 10:58:01 ----D---- C:\Program Files\Skype
2008-12-16 10:58:01 ----D---- C:\Program Files\Fichiers communs\Skype
2008-12-16 10:57:45 ----D---- C:\Documents and Settings\All Users\Application Data\Skype

======List of files/folders modified in the last 1 months======

2009-01-13 06:53:01 ----D---- C:\WINDOWS\Prefetch
2009-01-13 06:52:56 ----D---- C:\WINDOWS\system32\Catroot2
2009-01-13 06:39:41 ----D---- C:\WINDOWS
2009-01-13 06:38:29 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
2009-01-13 06:37:14 ----D---- C:\WINDOWS\system32\drivers
2009-01-12 22:56:20 ----D---- C:\Program Files\eMule
2009-01-12 22:54:42 ----A---- C:\WINDOWS\NeroDigital.ini
2009-01-12 22:34:20 ----D---- C:\Program Files\Webtarot
2009-01-12 21:22:25 ----D---- C:\WINDOWS\Debug
2009-01-12 20:16:46 ----D---- C:\WINDOWS\system32
2009-01-12 12:03:23 ----HD---- C:\WINDOWS\inf
2009-01-12 07:24:15 ----D---- C:\Program Files\Microsoft ActiveSync
2009-01-12 07:13:46 ----RD---- C:\Program Files
2009-01-10 18:28:46 ----N---- C:\WINDOWS\SchedLgU.Txt
2009-01-10 13:38:21 ----HD---- C:\Program Files\InstallShield Installation Information
2009-01-10 11:08:18 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-01-09 20:51:20 ----SHD---- C:\WINDOWS\Installer
2009-01-09 20:27:14 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-01-09 20:22:38 ----D---- C:\WINDOWS\system32\CatRoot
2009-01-09 20:14:32 ----D---- C:\WINDOWS\system32\config
2009-01-09 20:14:20 ----D---- C:\WINDOWS\system32\wbem
2009-01-09 20:14:19 ----D---- C:\WINDOWS\Registration
2009-01-09 18:58:49 ----D---- C:\WINDOWS\security
2009-01-09 09:38:21 ----D---- C:\Program Files\Fichiers communs
2009-01-09 07:45:29 ----D---- C:\Program Files\Lavasoft
2009-01-08 20:25:40 ----DC---- C:\WINDOWS\system32\DRVSTORE
2009-01-08 19:56:17 ----D---- C:\Program Files\PC Tools Firewall Plus
2009-01-08 12:59:50 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-01-08 12:11:07 ----D---- C:\WINDOWS\Minidump
2009-01-08 12:08:42 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-08 11:52:51 ----A---- C:\WINDOWS\system.ini
2009-01-08 11:49:21 ----D---- C:\WINDOWS\ERDNT
2009-01-08 11:48:55 ----D---- C:\Program Files\DAEMON Tools
2009-01-08 11:48:30 ----D---- C:\WINDOWS\AppPatch
2009-01-08 11:44:51 ----RASH---- C:\boot.ini
2009-01-08 08:18:50 ----D---- C:\Program Files\Windows Live Safety Center
2009-01-08 07:52:50 ----D---- C:\Program Files\Mozilla Firefox
2009-01-07 10:25:15 ----RSD---- C:\WINDOWS\assembly
2009-01-07 09:33:54 ----D---- C:\WINDOWS\Microsoft.NET
2009-01-07 09:17:27 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-01-07 09:08:05 ----D---- C:\Program Files\Conduit
2009-01-07 08:59:25 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-01-06 10:57:09 ----D---- C:\WINDOWS\WinSxS
2009-01-03 12:52:45 ----D---- C:\Program Files\Google
2009-01-03 12:51:43 ----D---- C:\Program Files\Unlocker
2009-01-03 09:56:12 ----SD---- C:\WINDOWS\Tasks
2009-01-01 18:26:09 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-12-18 17:43:07 ----SD---- C:\Documents and Settings\Pascal C\Application Data\Microsoft
2008-12-18 17:43:00 ----D---- C:\Program Files\Windows Live
2008-12-18 17:36:45 ----D---- C:\Program Files\Fichiers communs\Microsoft Shared
2008-12-18 15:03:30 ----D---- C:\WINDOWS\ie7updates
2008-12-18 15:03:04 ----HD---- C:\WINDOWS\$hf_mig$
2008-12-14 09:33:27 ----D---- C:\Documents and Settings

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2008-10-30 75072]
R1 ElbyCDIO;ElbyCDIO Driver; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [2007-08-07 25160]
R1 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40576]
R1 pctgntdi;pctgntdi; \??\C:\WINDOWS\system32\drivers\pctgntdi.sys []
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2007-03-01 28352]
R2 Aspi32;Aspi32; C:\WINDOWS\System32\drivers\aspi32.sys [2005-11-21 16512]
R2 GenPort;GenPort; C:\WINDOWS\system32\drivers\GenPort.sys [1997-10-08 4832]
R2 irda;Protocole IrDA; C:\WINDOWS\system32\DRIVERS\irda.sys [2008-04-13 88192]
R2 MapMem;MapMem; C:\WINDOWS\system32\drivers\MapMem.sys [1997-10-08 6816]
R2 NTRemap;NTRemap; C:\WINDOWS\system32\drivers\NTRemap.sys [1997-10-08 6336]
R2 PCTAppEvent;PCTAppEvent Driver; \??\C:\WINDOWS\system32\drivers\PCTAppEvent.sys []
R3 avgntflt;avgntflt; \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgntflt.sys []
R3 cmpci;C-Media PCI Audio Driver (WDM); C:\WINDOWS\system32\drivers\cmaudio.sys [2002-07-16 379726]
R3 ElbyCDFL;ElbyCDFL; C:\WINDOWS\System32\Drivers\ElbyCDFL.sys [2007-02-16 34760]
R3 FETNDISB;VIA Rhine Family Fast Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5b.sys [2004-04-15 42496]
R3 HidUsb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 Iviaspi;IVI ASPI Shell; C:\WINDOWS\system32\drivers\iviaspi.sys [2003-09-10 21060]
R3 LVPr2Mon;Logitech LVPr2Mon Driver; C:\WINDOWS\system32\DRIVERS\LVPr2Mon.sys [2007-10-11 25624]
R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12288]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-10-07 6133856]
R3 pctplfw;pctplfw; \??\C:\WINDOWS\system32\drivers\pctplfw.sys []
R3 Pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2003-09-19 10368]
R3 Rasirda;Miniport réseau étendu (IrDA); C:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 SFilter;PCTools Driver; C:\WINDOWS\system32\DRIVERS\pctfw.sys [2008-09-22 97408]
R3 SunkFilt;Alcor Micro Corp Reader; \??\C:\WINDOWS\System32\Drivers\sunkfilt.sys []
R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Pilote de concentrateur standard USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 wceusbsh;Windows CE USB Serial Host Driver; C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2006-11-06 28672]
S1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys []
S1 kbdhid;Pilote HID de clavier; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14720]
S2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys []
S3 ayyb0c9r;ayyb0c9r; C:\WINDOWS\system32\drivers\ayyb0c9r.sys []
S3 CCDECODE;Décodeur sous-titre fermé; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 CoachUsb;Coach Digital Camera on USB; C:\WINDOWS\system32\DRIVERS\CoachUsb.sys [2007-02-02 50176]
S3 CoachVid;CoachVid; C:\WINDOWS\system32\DRIVERS\CoachVid.sys [2007-02-02 45280]
S3 cusbohcn;cusbohcn; \??\C:\DOCUME~1\PASCAL~1\LOCALS~1\Temp\cusbohcn.sys []
S3 hcw95bda;Hauppauge MOD7700 Tuner Driver; C:\WINDOWS\System32\Drivers\hcw95bda.sys [2007-04-04 467456]
S3 hcw95rc;Hauppauge MOD7700 IR Driver; C:\WINDOWS\system32\DRIVERS\hcw95rc.sys [2007-04-04 15488]
S3 KS-959;Kingsun KS-959 USB Infrared Adapter; C:\WINDOWS\system32\DRIVERS\KS-959.sys [2005-10-20 19034]
S3 LVcKap;Logitech AEC Driver; C:\WINDOWS\system32\DRIVERS\LVcKap.sys [2007-10-19 2109976]
S3 LVMVDrv;Logitech Machine Vision Engine Loader; C:\WINDOWS\system32\DRIVERS\LVMVDrv.sys [2007-10-11 2142488]
S3 MPE;Filtre BDA MPE; C:\WINDOWS\system32\DRIVERS\MPE.sys [2008-04-13 15232]
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;Codec NABTS/FEC VBI; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Connection TV/vidéo Microsoft; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 Pcouffin;Low level access layer for CD devices; C:\WINDOWS\System32\Drivers\Pcouffin.sys []
S3 QCDonner;Logitech QuickCam Express; C:\WINDOWS\system32\DRIVERS\OVCD.sys [2001-08-17 28032]
S3 S3Psddr;S3Psddr; C:\WINDOWS\system32\DRIVERS\s3gnbm.sys [2004-08-13 167168]
S3 SLIP;Détrameur décalage BDA; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 TPP200;USB Storage Adapter V2 (TPP); C:\WINDOWS\system32\DRIVERS\TPP200.SYS [2001-10-05 35541]
S3 TVICHW32;TVICHW32; \??\C:\WINDOWS\system32\DRIVERS\TVICHW32.SYS []
S3 usbbus;LGE Mobile Composite USB Device; C:\WINDOWS\system32\DRIVERS\lgusbbus.sys []
S3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 UsbDiag;LGE Mobile USB Serial Port; C:\WINDOWS\system32\DRIVERS\lgusbdiag.sys []
S3 USBModem;LGE Mobile USB Modem; C:\WINDOWS\system32\DRIVERS\lgusbmodem.sys []
S3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Pilote de scanneur USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbvideo;Périphérique vidéo USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-13 121984]
S3 VIAudio;Vinyl AC'97 Audio Controller (WDM); C:\WINDOWS\system32\drivers\vinyl97.sys [2005-11-24 203776]
S3 WSTCODEC;Codec Teletext standard; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys []
S4 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys []
S4 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys []
S4 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirScheduler;Avira AntiVir Personal - Free Antivirus Scheduler; C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe [2008-10-15 68865]
R2 AntiVirService;Avira AntiVir Personal - Free Antivirus Guard; C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe [2008-10-15 151297]
R2 Irmon;Moniteur infrarouge; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 LVCOMSer;LVCOMSer; C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe [2007-10-19 186904]
R2 LVPrcSrv;Process Monitor; C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe [2007-10-19 141848]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2007-09-20 853288]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-10-07 163908]
R2 PCToolsFirewallPlus;PC Tools Firewall Plus; C:\Program Files\PC Tools Firewall Plus\FWService.exe [2008-12-11 146800]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2008-03-16 66872]
R2 PnkBstrB;PnkBstrB; C:\WINDOWS\system32\PnkBstrB.exe [2008-03-16 103736]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2008-12-04 226640]
R3 NMIndexingService;NMIndexingService; C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe [2007-09-20 382248]
R3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-11-03 918016]
S2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2009-01-08 611664]
S2 LVSrvLauncher;LVSrvLauncher; C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe [2007-10-19 141848]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2007-10-09 36864]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2007-10-11 864256]
S3 SandraDataSrv;SiSoftware Database Agent Service; C:\Program Files\SiSoftware\SiSoftware Sandra Lite XII.SP1\Win32\RpcDataSrv.exe [2007-12-12 213176]
S3 SandraTheSrv;SiSoftware Sandra Agent Service; C:\Program Files\SiSoftware\SiSoftware Sandra Lite XII.SP1\RpcSandraSrv.exe [2007-12-12 1253568]
S3 WmcCds;Windows Media Connect (WMC); c:\program files\windows media connect\mswmccds.exe [2004-08-11 483328]
S3 WmcCdsLs;Aide de Windows Media Connect (WMC); C:\Program Files\Windows Media Connect\mswmcls.exe [2004-08-11 28160]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-01-08 17272]
S4 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-01-08 144760]
S4 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-01-08 247160]
S4 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-01-08 349560]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2007-10-11 122880]

-----------------EOF-----------------


INFOS.TEXT

<code>info.txt logfile of random's system information tool 1.05 2009-01-13 06:53:21

======Uninstall list======

-->"C:\Program Files\InstallShield Installation Information\{0B168FED-B9EC-4DA8-AC17-9A41F284640B}\setup.exe" REMOVEALL
-->"C:\Program Files\InstallShield Installation Information\{2FCE4FC5-6930-40E7-A4F1-F862207424EF}\setup.exe" REMOVEALL
-->"C:\Program Files\InstallShield Installation Information\{F366D0C4-18F2-44A6-A4E7-7ED2DD37F3D3}\setup.exe" --u:{F366D0C4-18F2-44A6-A4E7-7ED2DD37F3D3}
-->C:\Program Files\InstallShield Installation Information\{C6CD52FA-0D47-4FF3-A5EF-D32B5AD98BD3}\setup.exe -runfromtemp -l0x040c -removeonly
-->C:\Program Files\Nero\Nero8\\nero\uninstall\UNNERO.exe /UNINSTALL
-->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
-->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
-->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
-->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
-->C:\WINDOWS\UNRecode.exe /UNINSTALL
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{40602E2C-AB5C-4887-8093-3BFE5B8B95B3}\setup.exe" REMOVEALL
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AEFD48FE-2A76-11D3-928B-00C04FB90523}\setup.exe"
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
7-Zip 4.52 beta-->"C:\Program Files\7-Zip\Uninstall.exe"
Ad-Aware-->MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 9 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A90000000001}
Airscanner Mobile Antivirus-->C:\Program Files\Microsoft ActiveSync\Airscanner Mobile Antivirus\Uninstall.exe Airscanner Mobile Antivirus
Album photo Microsoft 9-->C:\WINDOWS\system32\msiexec.exe /i {9F7FC79B-3059-4264-9450-39EB368E3225}
Apple Software Update-->MsiExec.exe /I{02DFF6B1-1654-411C-8D7B-FD6052EF016F}
Applian PicturePerfect-->C:\WINDOWS\iun506.exe C:\Program Files\Applian\Classic_Games\irunin.ini
Assistant de connexion Windows Live-->MsiExec.exe /I{D6E592B3-67DA-4BBB-9783-E1838FB253A2}
avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
CETuner-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E83B8E20-60E4-11D5-88D9-0002B338C36B}\Setup.exe" -uninst
Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
CloneCD-->"C:\Program Files\SlySoft\CloneCD\ccd-uninst.exe" /D="C:\Program Files\SlySoft\CloneCD"
C-Media 3D Audio-->C:\WINDOWS\CMIUnInstall.exe
Commandos Strike Force-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{544DB849-AB59-4C12-A333-2F214E24870F}\Setup.exe" -l0x40c -removeonly
Compatibility Pack for the 2007 Office system-->MsiExec.exe /X{90120000-0020-040C-0000-0000000FF1CE}
ConquerCam 2.6-->"C:\Program Files\ConquerCam\unins000.exe"
Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Correctif pour Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Eazel-FR Toolbar-->C:\PROGRA~1\Eazel-FR\UNWISE.EXE /U C:\PROGRA~1\Eazel-FR\INSTALL.LOG
eMule-->"C:\Program Files\eMule\Uninstall.exe"
EPSON Attach To Email-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{20C45B32-5AB6-46A4-94EF-58950CAF05E5} /l1033 ADDREMOVEDLG
EPSON Copy Utility 3-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{67EDD823-135A-4D59-87BD-950616D6E857}\SETUP.EXE" -l0x40c -UnInstall
EPSON Easy Photo Print-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F19D07BC-6240-49D3-BA5C-59B015DF8916}\SETUP.EXE" -l0x40c UNINST
EPSON File Manager-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E86BC406-944E-41F6-ADE6-2C136734C96B}\Setup.exe" -l0x40c UNINST
EPSON Image Clip Palette-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{314F6D08-A8B7-11D8-8446-0050BA1D384D}\Setup.exe" -l0x40c -u
EPSON Logiciel imprimante-->C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R
EPSON Scan Assistant-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}\Setup.exe" -l0x40c -u
EPSON Scan-->C:\Program Files\epson\escndv\setup\setup.exe /r
ESDX4800_4200 Guide util.-->C:\Program Files\EPSON\TPMANUAL\ESDX4800_4200\USE_G\DOCUNINS.EXE
Extension HighMAT pour l'Assistant Graver un CD de Microsoft Windows XP-->MsiExec.exe /X{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}
FindyKill-->C:\Program Files\FindyKill\Uninstal.exe
First to Fight-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{494933D5-BC91-428B-94C9-CDC26DCA5DBA} /l1036
Hauppauge French Help Files and Resources-->C:\PROGRA~1\WinTV\UNHLPfra.EXE C:\PROGRA~1\WinTV\WTV2Kfra.LOG
Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
HP Image Transfer v.1.9.7b-->C:\Program Files\Microsoft ActiveSync\HP Image Transfer\Uninst.exe
Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
Installation Windows Live-->MsiExec.exe /I{3CCB732A-E472-4CF9-B1EE-F18365341FE0}
InterVideo FilterSDK for Hauppauge-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2227E1FA-01F5-483C-AB0E-2A308E900B3D}\setup.exe" REMOVEALL
InterVideo Launcher-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8AEEE6D6-C95D-465A-B8D3-B7AE2FA7B8B4}\setup.exe" REMOVEALL
iPAQ WebReg-->MsiExec.exe /I{D37C6152-89DF-4D29-83CF-666200D5F398}
Java(TM) 6 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
Java(TM) 6 Update 3-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java(TM) 6 Update 4-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160040}
Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Junk Mail filter update-->MsiExec.exe /I{4AB8B41B-3AF1-46BE-99B0-0ACD3B300C0A}
La Marmite du Chef 6.4.0-->"C:\Program Files\El Juky\La Marmite du Chef\unins000.exe"
Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
LimeWire 4.18.8-->"C:\Program Files\LimeWire\uninstall.exe"
Logitech QuickCam-->MsiExec.exe /X{945AC98B-3DC8-45BE-BAE0-22CEEE37A103}
Magic Button-->C:\Program Files\Microsoft ActiveSync\Magic Button\Uninstall.exe Magic Button
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Medal of Honor Débarquement allié(tm) En Formation-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7914BE1E-F186-4790-B8F4-9F63C52A41C1}\Setup.exe" -l0x40c
Medal of Honor Débarquement Allié(tm) l'Offensive v2.40 Patch-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DF9046D6-5F1F-40B6-9782-3DC2D902D391}\Setup.exe" -l0x40c
Medal of Honor Débarquement Allié(tm) l'Offensive-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{823A68CC-3049-4A6B-8F63-7DC85E4BB1C9}\Setup.exe" -l0x40c
Medal of Honor débarquement allié-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0DEA94ED-915A-4834-A87E-388D012C8E02}\Setup.exe" -l0x40c
Microsoft .NET Compact Framework 1.0 SP3-->MsiExec.exe /I{7A0BAED2-066E-4B4F-8FA5-472A4655F4C2}
Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
Microsoft .NET Framework 3.0 Service Pack 1-->MsiExec.exe /I{2BA00471-0328-3743-93BD-FA813353A783}
Microsoft .NET Framework 3.5-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5\setup.exe
Microsoft .NET Framework 3.5-->MsiExec.exe /I{2FC099BD-AC9B-33EB-809C-D332E1B27C40}
Microsoft ActiveSync-->MsiExec.exe /I{99052DB7-9592-4522-A558-5417BBAD48EE}
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office XP Professional avec FrontPage-->MsiExec.exe /I{9028040C-6000-11D3-8CFE-0050048383C9}
Microsoft Office XP Web Components-->MsiExec.exe /I{9026040C-6000-11D3-8CFE-0050048383C9}
Microsoft Photo Pro 9-->C:\WINDOWS\system32\msiexec.exe /i {DBA8B9E1-C6FF-4624-9598-73D3B41A0905}
Microsoft Search Enhancement Pack-->MsiExec.exe /I{299CF645-48C7-4FA1-8BCD-5CE200CF180D}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft Small Basic v0.2-->MsiExec.exe /I{3C57A49D-0C79-48C0-ABBE-50B06E566C2D}
Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729-->MsiExec.exe /X{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}
Microsoft Windows SDK for Visual Studio 2008 Express Tools for .NET Framework-->MsiExec.exe /X{AB47EEE8-507B-331F-AA28-B7C7257F014C}
Microsoft Windows SDK for Visual Studio 2008 Express Tools for Win32-->MsiExec.exe /X{07FCBED5-94C3-4F94-B9D3-360FA27C7B06}
Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Lecteur Windows Media 10 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
Mozilla Firefox (3.0.4)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 6.0 Parser (KB933579)-->MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
Multimedia Card Reader-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{CA529363-D0F2-41EA-B44B-D7515A254645}
Nero 8-->MsiExec.exe /X{B4649EFB-54CB-42AB-8536-8FED519E1036}
neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
NS BASIC Corporation NS Basic/CE 6.5-->"C:\WINDOWS\epsuninst.exe" "C:\Program Files\NSBasic\CE\uninst.dat"
NVIDIA Drivers-->C:\WINDOWS\system32\nvuninst.exe UninstallGUI
OpenOffice.org Installer 1.0-->MsiExec.exe /X{3A2AF807-9F9F-43C9-A24A-17B617238B74}
Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
Palringo-->C:\Program Files\Microsoft ActiveSync\Palringo\Uninstall.exe Palringo
PC Tools Firewall Plus 5.0-->C:\Program Files\PC Tools Firewall Plus\unins000.exe /LOG
PCI Audio Driver-->cmuninst.exe
PocketGEAR SDIO WLAN Card-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{B37D5BD3-27F5-4356-95F4-56702E9E9AE1}
Quick GPS Connection Data Download Manager-->MsiExec.exe /I{F5AC3121-FB42-48CA-8EE4-FC16D5339F92}
QuickTime-->C:\WINDOWS\unvise32qt.exe C:\WINDOWS\system32\QuickTime\Uninstall.log
REALbasic 2007r3-->MsiExec.exe /I{31B654EA-78CC-4F61-AB29-7BC7A7FBBFA6}
RemoteControl II-->C:\Program Files\Microsoft ActiveSync\RemoteControl II\Uninstall.exe RemoteControl II
S3Display-->s3uninst.exe -reg 5 'HKLM\Software\S3\S3Uninst\S3Display'
S3Gamma2-->s3uninst.exe -reg 5 'HKLM\Software\S3\S3Uninst\S3Gamma2'
S3Info2-->s3uninst.exe -reg 5 'HKLM\Software\S3\S3Uninst\S3Info2'
S3Overlay-->s3uninst.exe -reg 5 'HKLM\Software\S3\S3Uninst\S3Overlay'
Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
SiSoftware Sandra Lite XII.SP1-->"C:\Program Files\SiSoftware\SiSoftware Sandra Lite XII.SP1\unins000.exe"
Skype™ 3.8-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
Skype™ for Windows Mobile 2.5-->"C:\Program Files\Microsoft ActiveSync\Skype for Windows Mobile\unins000.exe"
Spb Diary-->C:\Program Files\Microsoft ActiveSync\Spb Diary\Uninstall.exe Spb Diary
Spb Mobile Shell-->C:\Program Files\Microsoft ActiveSync\Spb Mobile Shell\Uninstall.exe Spb Mobile Shell
Spb Pocket Plus-->C:\Program Files\Microsoft ActiveSync\Spb Pocket Plus\Uninstall.exe Spb Pocket Plus
Spb Weather-->C:\Program Files\Microsoft ActiveSync\Spb Weather\Uninstall.exe Spb Weather
Spybot - Search & Destroy 1.4-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
System Requirements Lab-->C:\Program Files\SystemRequirementsLab\Uninstall.exe
TomTom HOME-->C:\Program Files\InstallShield Installation Information\{CE325D55-FCAF-4273-BB79-069BB8747270}\setup.exe -runfromtemp -l0x040c -removeonly -removeonly
TPP Storage Driver Installation-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E258A840-7E9A-443A-B156-67102C48BF17}\Setup.exe" NotFirstInstall
Unlocker 1.8.5-->C:\Program Files\Unlocker\uninst.exe
USB Storage Adapter (TPP)-->tppun.exe TPP725
USB Storage Adapter V2 (TPP)-->tppun.exe TPP200
USB Storage Adapter V3 (TPP)-->tppun.exe TPP300
Utilitaire de sauvegarde Windows-->MsiExec.exe /I{76EFFC7C-17A6-479D-9E47-8E658C1695AE}
VCRedistSetup-->MsiExec.exe /I{3921A67A-5AB1-4E48-9444-C71814CF3027}
VIA Platform Device Manager-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{20D4A895-748C-4D88-871C-FDB1695B0169}
VideoLAN VLC media player 0.8.6c-->C:\Program Files\VideoLAN\VLC\uninstall.exe
WebTarot 1.23-->"C:\Program Files\Webtarot\unins000.exe"
Winamp (remove only)-->"C:\Program Files\Winamp\UninstWA.exe"
Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Live Call-->MsiExec.exe /I{01523985-2098-43AF-9C97-12B07BE02A9B}
Windows Live Communications Platform-->MsiExec.exe /I{F69E83CF-B440-43F8-89E6-6EA80712109B}
Windows Live Mail-->MsiExec.exe /I{63DC2DA0-2A6C-4C38-9249-B75395458657}
Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
Windows Live OneCare safety scanner-->RunDll32.exe "C:\Program Files\Windows Live Safety Center\wlscCore.dll",UninstallFunction WLSC_SCANNER_PRODUCT
Windows Live Toolbar-->MsiExec.exe /X{915809D6-1F93-45F2-9699-5F1DA64DC24B}
Windows Media Connect-->msiexec.exe /I {F6869CD2-3DB4-476D-A4C7-B3AE7C3ACF7B}
Windows Media Connect-->MsiExec.exe /I{F6869CD2-3DB4-476D-A4C7-B3AE7C3ACF7B}
0
jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 040
 
télécharge combofix (par sUBs) ici :

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

et enregistre le sur le bureau
sous le nom de antibagle. Fais le avant que le fichier ne soit enregistré sur le bureau]

déconnecte toi d'internet et ferme toutes tes applications.

désactive tes protections (antivirus, parefeu, garde en temps réel de l'antispyware)

double-clique sur combofix.exe et suis les instructions

à la fin, il va produire un rapport C:\ComboFix.txt

réactive ton parefeu, ton antivirus, la garde de ton antispyware

copie/colle le rapport C:\ComboFix.txt dans ta prochaine réponse.

Attention, n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi.

Tu as un tutoriel complet ici :

https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
pascal21850 Messages postés 5 Statut Membre
 
bonjour et merci pour l'aide
voici le rapport combofix auquel je ne comprends rien lol!!!

bonne lecture!!
ComboFix 09-01-11.04 - Pascal C 2009-01-13 11:50:05.2 - NTFSx86
Microsoft Windows XP Édition familiale  5.1.2600.3.1252.1.1036.18.1535.1074 [GMT 1:00]
Lancé depuis: c:\documents and settings\Pascal C\Bureau\antibagle.exe
AV: avast! antivirus 4.8.1201 [VPS 081231-1] *On-access scanning disabled* (Outdated)
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Outdated)
FW: PC Tools Firewall Plus *disabled*
 * Un nouveau point de restauration a été créé
.

((((((((((((((((((((((((((((((((((((   Autres suppressions   ))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat

----- BITS: Il y a peut-être des sites infectés -----

hxxp://gllto.glpals.com
.
(((((((((((((((((((((((((((((   Fichiers créés du 2008-12-13 au 2009-01-13  ))))))))))))))))))))))))))))))))))))
.

2009-01-13 06:52 . 2009-01-13 06:53	<REP>	d--------	C:\rsit
2009-01-12 07:13 . 2009-01-12 07:13	<REP>	d--------	c:\program files\NSBasic
2009-01-10 19:36 . 2009-01-10 19:37	<REP>	d--------	c:\program files\SBSH Calendar Touch
2009-01-10 13:38 . 2009-01-10 13:38	<REP>	d--------	c:\program files\Paragon Software (MCD)
2009-01-10 10:49 . 2009-01-13 09:15	<REP>	d--------	c:\program files\FindyKill
2009-01-09 20:36 . 2009-01-12 16:19	<REP>	d--------	c:\program files\ConquerCam
2009-01-09 20:27 . 2007-02-02 05:35	114,688	-ra------	c:\windows\system32\JpegCode.dll
2009-01-09 20:27 . 2007-02-02 05:35	45,280	-ra------	c:\windows\system32\drivers\CoachVid.sys
2009-01-09 20:27 . 2007-02-02 05:35	16,896	-ra------	c:\windows\system32\CoachDlg.dll
2009-01-09 20:21 . 2007-02-02 05:35	98,816	-ra------	c:\windows\system32\CoachWia.dll
2009-01-09 20:21 . 2007-02-02 05:35	50,176	-ra------	c:\windows\system32\drivers\CoachUsb.sys
2009-01-09 20:21 . 2007-02-02 05:35	14,336	-ra------	c:\windows\system32\CoachWrp.dll
2009-01-09 20:13 . 2009-01-09 20:13	<REP>	d--------	c:\program files\REAL Software
2009-01-09 20:13 . 2009-01-09 20:13	<REP>	d--------	c:\program files\IM+ 5.42 for PocketPC
2009-01-09 20:13 . 2009-01-09 20:13	<REP>	d--------	c:\program files\Fichiers communs\Wise Installation Wizard
2009-01-09 20:13 . 2009-01-09 20:13	<REP>	d--------	c:\program files\EoRezo
2009-01-09 20:13 . 2009-01-09 20:13	<REP>	d--------	c:\program files\Eazel-FR
2009-01-09 20:13 . 2009-01-09 20:13	<REP>	d--------	c:\program files\CamStudio(2)
2009-01-09 20:13 . 2009-01-09 20:13	<REP>	d--------	c:\program files\AskTBar
2009-01-09 20:13 . 2009-01-09 20:13	<REP>	d--------	C:\PocketTiME
2009-01-09 20:13 . 2009-01-09 20:13	<REP>	d--------	C:\lgupload
2009-01-09 20:13 . 2009-01-09 20:13	<REP>	d--------	c:\documents and settings\Pascal C\Application Data\REALbasic 2006
2009-01-09 20:12 . 2009-01-09 20:12	<REP>	d--------	c:\documents and settings\All Users\Application Data\Avira
2009-01-09 18:56 . 2009-01-09 20:12	<REP>	d--------	c:\documents and settings\All Users\Application Data\Avira(2)
2009-01-09 18:47 . 2009-01-09 20:13	<REP>	d--------	c:\program files\The Cleaner Demo
2009-01-09 13:04 . 2007-12-17 21:04	44,032	--a------	c:\windows\system32\axvlc.oca
2009-01-09 12:31 . 2009-01-09 20:51	<REP>	d--------	c:\program files\Microsoft CAPICOM 2.1.0.2
2009-01-09 09:38 . 2009-01-09 09:38	<REP>	d--------	c:\documents and settings\Pascal C\Application Data\ArcSoft
2009-01-09 09:37 . 2009-01-09 09:37	<REP>	d--------	c:\program files\ArcSoft
2009-01-09 09:18 . 2007-03-22 20:05	3,584	--a------	c:\windows\system32\CoachDlg.lng
2009-01-09 07:56 . 2009-01-09 20:13	<REP>	d--------	c:\program files\Imaveo
2009-01-09 07:38 . 2009-01-09 07:39	32,122,392	--a------	C:\CAPTURE.AVI
2009-01-08 20:24 . 2009-01-09 20:23	<REP>	d--------	c:\documents and settings\All Users\Application Data\Logishrd
2009-01-08 20:23 . 2009-01-08 20:23	<REP>	d--------	c:\program files\Logitech
2009-01-08 20:23 . 2009-01-08 20:25	<REP>	d--------	c:\program files\Fichiers communs\LogiShrd
2009-01-08 20:23 . 2009-01-08 20:23	<REP>	d--------	c:\documents and settings\All Users\Application Data\Logitech
2009-01-08 20:07 . 2009-01-08 20:08	25	--a------	c:\windows\OverlayXP.ini
2009-01-08 20:03 . 2009-01-08 20:07	<REP>	d--------	c:\documents and settings\All Users\Application Data\webcamXP5
2009-01-08 13:31 . 2009-01-08 13:31	<REP>	d--------	c:\program files\Fichiers communs\PC Tools
2009-01-08 13:31 . 2008-12-11 08:38	159,600	--a------	c:\windows\system32\drivers\pctgntdi.sys
2009-01-08 13:31 . 2008-12-11 12:32	132,976	--a------	c:\windows\system32\drivers\PCTCore.sys
2009-01-08 13:31 . 2008-09-22 12:29	97,408	--a------	c:\windows\system32\drivers\pctfw.sys
2009-01-08 13:31 . 2008-12-11 17:01	95,640	--a------	c:\windows\system32\drivers\pctplfw.sys
2009-01-08 13:31 . 2008-12-11 12:32	73,840	--a------	c:\windows\system32\drivers\PCTAppEvent.sys
2009-01-08 12:05 . 2009-01-08 12:05	<REP>	d--------	c:\program files\Avira
2009-01-08 11:04 . 2009-01-08 11:22	<REP>	d--------	C:\Rooter$
2009-01-08 09:11 . 2001-08-17 22:05	48,000	--a------	c:\windows\system32\drivers\OVCam2.sys
2009-01-08 09:11 . 2001-08-17 22:05	48,000	--a--c---	c:\windows\system32\dllcache\ovcam2.sys
2009-01-07 08:57 . 2009-01-04 18:38	38,496	--a------	c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-07 08:57 . 2009-01-04 18:38	15,504	--a------	c:\windows\system32\drivers\mbam.sys
2009-01-05 19:06 . 2009-01-05 19:06	<REP>	d--------	c:\program files\Microsoft SDKs
2009-01-05 12:41 . 2009-01-05 12:42	<REP>	d--------	c:\program files\SBSH PhoneWeaver
2009-01-04 20:56 . 2009-01-04 20:56	<REP>	d--------	c:\windows\Agenda One
2009-01-03 13:56 . 2009-01-03 13:56	<REP>	d--------	C:\Games
2009-01-03 12:52 . 2009-01-03 12:52	<REP>	d--------	c:\program files\pocketGEAR
2009-01-01 18:25 . 2009-01-01 18:25	<REP>	d--------	c:\program files\Microsoft.NET
2009-01-01 09:50 . 2009-01-03 12:51	<REP>	d--------	c:\program files\RegCleaner
2008-12-31 14:21 . 2008-12-31 14:21	<REP>	d--------	c:\program files\CounterPath
2008-12-18 17:45 . 2009-01-13 07:35	<REP>	d--------	c:\documents and settings\Pascal C\Tracing
2008-12-18 17:43 . 2008-12-18 17:43	<REP>	d--------	c:\program files\Microsoft Silverlight
2008-12-18 17:41 . 2008-12-18 17:41	<REP>	d--------	c:\program files\Microsoft Sync Framework
2008-12-18 17:37 . 2009-01-09 07:07	<REP>	d--------	c:\program files\Microsoft
2008-12-18 17:36 . 2008-12-18 17:36	<REP>	d--------	c:\program files\Windows Live SkyDrive
2008-12-18 17:23 . 2008-12-18 17:23	<REP>	d--------	c:\program files\Fichiers communs\Windows Live
2008-12-16 20:29 . 1997-10-08 03:52	393,216	--a------	c:\windows\system32\glide2x.dll
2008-12-16 20:29 . 1996-08-16 13:49	298,496	--a------	c:\windows\uninst.exe
2008-12-16 20:29 . 1997-10-08 03:04	6,816	--a------	c:\windows\system32\drivers\MAPMEM.SYS
2008-12-16 20:29 . 1997-10-08 03:04	6,336	--a------	c:\windows\system32\drivers\NTREMAP.SYS
2008-12-16 20:29 . 1997-10-08 03:04	4,832	--a------	c:\windows\system32\drivers\genport.sys
2008-12-16 20:02 . 1997-06-13 08:56	56,832	--a------	c:\windows\system32\iyvu9_32.dll
2008-12-16 16:27 . 2009-01-04 18:32	<REP>	d--------	c:\program files\City Interactive
2008-12-16 16:06 . 2008-12-16 16:06	98,304	--a------	c:\windows\system32\CmdLineExt.dll
2008-12-16 16:05 . 2008-12-18 14:37	<REP>	d--------	c:\program files\GameShadow
2008-12-16 15:58 . 2008-12-16 15:58	<REP>	d--------	c:\program files\Eidos
2008-12-16 11:00 . 2009-01-12 20:18	<REP>	d--------	c:\documents and settings\Pascal C\Application Data\skypePM
2008-12-16 11:00 . 2008-12-16 11:00	56	--ah-----	c:\windows\system32\ezsidmv.dat
2008-12-16 10:58 . 2008-12-16 10:58	<REP>	d--------	c:\program files\Skype
2008-12-16 10:58 . 2008-12-16 10:58	<REP>	d--------	c:\program files\Fichiers communs\Skype
2008-12-16 10:58 . 2009-01-13 08:40	<REP>	d--------	c:\documents and settings\Pascal C\Application Data\Skype
2008-12-16 10:57 . 2008-12-16 10:58	<REP>	d--------	c:\documents and settings\All Users\Application Data\Skype
2008-12-14 09:33 . 2006-01-17 16:37	<REP>	d--------	c:\documents and settings\Administrateur\WINDOWS
2008-12-14 09:33 . 2004-10-21 22:00	<REP>	d--h-----	c:\documents and settings\Administrateur\Voisinage réseau
2008-12-14 09:33 . 2004-10-21 22:00	<REP>	d--h-----	c:\documents and settings\Administrateur\Voisinage d'impression
2008-12-14 09:33 . 2004-10-21 20:20	<REP>	d--h-----	c:\documents and settings\Administrateur\Modèles
2008-12-14 09:33 . 2007-12-07 04:58	<REP>	dr-------	c:\documents and settings\Administrateur\Mes documents
2008-12-14 09:33 . 2007-12-07 04:58	<REP>	dr-------	c:\documents and settings\Administrateur\Menu Démarrer
2008-12-14 09:33 . 2007-12-07 04:58	<REP>	dr-------	c:\documents and settings\Administrateur\Favoris
2008-12-14 09:33 . 2004-10-21 22:00	<REP>	d--------	c:\documents and settings\Administrateur\Bureau
2008-12-14 09:33 . 2009-01-09 20:14	<REP>	d--------	c:\documents and settings\Administrateur

.
((((((((((((((((((((((((((((((((((   Compte-rendu de Find3M   ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-13 08:31	---------	d-----w	c:\program files\Spybot - Search & Destroy
2009-01-13 08:31	---------	d-----w	c:\program files\Microsoft ActiveSync
2009-01-13 08:31	---------	d-----w	c:\program files\eMule
2009-01-13 07:47	---------	d---a-w	c:\documents and settings\All Users\Application Data\TEMP
2009-01-13 06:04	---------	d-----w	c:\program files\Webtarot
2009-01-10 12:38	---------	d--h--w	c:\program files\InstallShield Installation Information
2009-01-09 06:45	---------	d-----w	c:\program files\Lavasoft
2009-01-08 18:56	---------	d-----w	c:\program files\PC Tools Firewall Plus
2009-01-08 11:08	---------	d-----w	c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-08 10:48	---------	d-----w	c:\program files\DAEMON Tools
2009-01-08 07:18	---------	d-----w	c:\program files\Windows Live Safety Center
2009-01-07 08:08	---------	d-----w	c:\program files\Conduit
2009-01-07 07:59	---------	d-----w	c:\program files\Malwarebytes' Anti-Malware
2009-01-03 11:52	---------	d-----w	c:\program files\Google
2009-01-03 11:51	---------	d-----w	c:\program files\Unlocker
2008-12-18 16:43	---------	d-----w	c:\program files\Windows Live
2008-12-10 18:54	---------	d-----w	c:\program files\Java
2008-12-10 05:07	---------	d-----w	c:\documents and settings\Pascal C\Application Data\Malwarebytes
2008-12-10 05:07	---------	d-----w	c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-08 19:42	---------	d-----w	c:\documents and settings\Pascal C\Application Data\LimeWire
2008-12-07 10:13	---------	d-----w	c:\program files\Windows Live Toolbar
2008-12-07 10:05	---------	d-----w	c:\program files\Navilog1
2008-12-02 21:37	49,480	----a-w	c:\windows\system32\sirenacm.dll
2008-11-30 20:11	---------	d-----w	c:\documents and settings\Pascal C\Application Data\WeatherWatcherLive
2008-11-30 20:09	---------	d-----w	c:\documents and settings\Pascal C\Application Data\WeatherWatcher
2008-11-29 12:46	---------	d-----w	c:\program files\HP
2008-11-29 12:44	---------	d-----w	c:\program files\Quick GPS Connection Data Download Manager
2008-10-30 18:43	60,960	----a-w	c:\documents and settings\Pascal C\Application Data\GDIPFONTCACHEV1.DAT
2008-10-23 12:36	286,720	----a-w	c:\windows\system32\gdi32.dll
2008-10-16 20:18	826,368	----a-w	c:\windows\system32\wininet.dll
2008-10-16 13:13	202,776	----a-w	c:\windows\system32\wuweb.dll
2008-10-16 13:13	1,809,944	----a-w	c:\windows\system32\wuaueng.dll
2008-10-16 13:12	561,688	----a-w	c:\windows\system32\wuapi.dll
2008-10-16 13:12	323,608	----a-w	c:\windows\system32\wucltui.dll
2008-10-16 13:09	92,696	----a-w	c:\windows\system32\cdm.dll
2008-10-16 13:09	51,224	----a-w	c:\windows\system32\wuauclt.exe
2008-10-16 13:09	43,544	----a-w	c:\windows\system32\wups2.dll
2008-10-16 13:08	34,328	----a-w	c:\windows\system32\wups.dll
2008-10-16 13:06	268,648	----a-w	c:\windows\system32\mucltui.dll
2008-10-16 13:06	208,744	----a-w	c:\windows\system32\muweb.dll
2008-03-16 21:06	22,328	----a-w	c:\documents and settings\Pascal C\Application Data\PnkBstrK.sys
2007-08-22 18:38	71	----a-w	c:\program files\Fichiers communs\appop.log
2001-10-05 10:53	21,866	----a-w	c:\program files\Fichiers communs\tppupd2k.dll
2008-09-17 19:31	32,768	--sha-w	c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008091720080918\index.dat
.

(((((((((((((((((((((((((((((   snapshot@2009-01-08_11.55.28.32   )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-01-09 19:21:29	15,086	----a-r	c:\windows\Installer\{945AC98B-3DC8-45BE-BAE0-22CEEE37A103}\ARPPRODUCTICON.exe
+ 2009-01-09 19:21:30	15,086	----a-r	c:\windows\Installer\{945AC98B-3DC8-45BE-BAE0-22CEEE37A103}\DesktopShortcut_10110FE91EE84A3DADFD1294F86BE5FC.exe
+ 2009-01-09 19:21:30	53,248	----a-r	c:\windows\Installer\{945AC98B-3DC8-45BE-BAE0-22CEEE37A103}\ProgramGroupShortcut_EFA2BBEBCF93493B904B1B970B8DFAB6.exe
- 2000-08-31 07:00:00	28,672	----a-w	c:\windows\NIRCMD.exe
+ 2000-08-31 07:00:00	29,696	----a-w	c:\windows\NIRCMD.exe
+ 2002-05-02 17:38:12	45,144	----a-w	c:\windows\system32\adocedt31.dll
+ 2007-10-21 17:38:06	516,832	----a-w	c:\windows\system32\capicom.dll
+ 2005-12-05 18:57:00	618,496	----a-w	c:\windows\system32\cmax40.dll
+ 2000-03-18 19:00:08	94,208	----a-w	c:\windows\system32\CMDLGD6.dll
+ 2008-04-14 03:33:28	47,616	-c--a-w	c:\windows\system32\dllcache\iyuv_32.dll
+ 2004-07-09 03:26:38	16,896	-c--a-w	c:\windows\system32\dllcache\msyuv.dll
+ 2004-07-09 03:27:28	48,512	-c--a-w	c:\windows\system32\dllcache\stream.sys
- 2001-08-23 15:47:20	8,192	-c--a-w	c:\windows\system32\dllcache\tsbyuv.dll
+ 2001-08-23 16:47:20	8,192	-c--a-w	c:\windows\system32\dllcache\tsbyuv.dll
+ 2008-04-14 03:33:48	54,784	-c--a-w	c:\windows\system32\dllcache\vfwwdm32.dll
+ 2008-05-09 11:15:51	45,376	----a-w	c:\windows\system32\drivers\avgntdd.sys
+ 2008-01-21 16:11:28	22,336	----a-w	c:\windows\system32\drivers\avgntmgr.sys
+ 2008-10-30 09:21:03	75,072	----a-w	c:\windows\system32\drivers\avipbb.sys
+ 2007-10-19 12:16:30	2,109,976	----a-w	c:\windows\system32\drivers\Lvckap.sys
+ 2007-10-11 17:59:02	2,142,488	----a-w	c:\windows\system32\drivers\LVMVdrv.sys
+ 2007-10-11 17:59:24	25,624	----a-w	c:\windows\system32\drivers\LVPr2Mon.sys
+ 2007-03-01 08:34:22	28,352	----a-w	c:\windows\system32\drivers\ssmdrv.sys
- 2008-04-13 18:45:15	49,408	----a-w	c:\windows\system32\drivers\stream.sys
+ 2004-07-09 03:27:28	48,512	----a-w	c:\windows\system32\drivers\stream.sys
+ 2006-01-13 13:02:12	548,864	----a-w	c:\windows\system32\ExMenu.dll
+ 2006-01-13 13:04:18	593,920	----a-w	c:\windows\system32\ExPropertiesList.dll
+ 2000-03-25 23:00:00	36,954	----a-w	c:\windows\system32\finance.dll
- 2008-04-14 02:33:27	47,616	----a-w	c:\windows\system32\iyuv_32.dll
+ 2008-04-14 03:33:28	47,616	----a-w	c:\windows\system32\iyuv_32.dll
+ 2000-07-13 14:27:00	69,725	----a-w	c:\windows\system32\mscecomdlg.dll
+ 2000-03-25 23:00:00	69,723	----a-w	c:\windows\system32\MSCECOMM.DLL
+ 2000-07-13 14:27:00	73,819	----a-w	c:\windows\system32\MSCEFILE.DLL
+ 2000-03-25 23:00:00	114,779	----a-w	c:\windows\system32\MSCEGRID.DLL
+ 2000-03-25 23:00:00	53,340	----a-w	c:\windows\system32\msceimage.dll
+ 2000-03-25 23:00:00	53,344	----a-w	c:\windows\system32\msceimagelist.dll
+ 2000-03-25 23:00:00	135,263	----a-w	c:\windows\system32\mscelistview.dll
+ 2000-03-25 23:00:00	82,014	----a-w	c:\windows\system32\mscepicture.dll
+ 2000-03-25 23:00:00	135,263	----a-w	c:\windows\system32\mscetabstrip.dll
+ 2000-03-25 23:00:00	77,919	----a-w	c:\windows\system32\mscetreeview.dll
+ 2000-07-24 14:10:00	77,918	----a-w	c:\windows\system32\mscewinsock.dll
- 2008-04-14 02:34:34	294,912	----a-w	c:\windows\system32\msh263.drv
+ 2008-04-14 03:34:34	294,912	----a-w	c:\windows\system32\msh263.drv
- 2008-04-14 02:33:34	16,896	----a-w	c:\windows\system32\msyuv.dll
+ 2004-07-09 03:26:38	16,896	----a-w	c:\windows\system32\msyuv.dll
+ 2006-01-25 16:58:58	53,248	----a-w	c:\windows\system32\NSBAddscript.dll
+ 2004-08-14 10:46:56	53,248	----a-w	c:\windows\system32\NSBPictB.dll
- 2009-01-06 09:58:45	62,450	----a-w	c:\windows\system32\perfc009.dat
+ 2009-01-10 10:08:18	62,518	----a-w	c:\windows\system32\perfc009.dat
- 2009-01-06 09:58:45	75,752	----a-w	c:\windows\system32\perfc00C.dat
+ 2009-01-10 10:08:18	75,824	----a-w	c:\windows\system32\perfc00C.dat
- 2009-01-06 09:58:45	404,046	----a-w	c:\windows\system32\perfh009.dat
+ 2009-01-10 10:08:18	404,250	----a-w	c:\windows\system32\perfh009.dat
- 2009-01-06 09:58:45	471,928	----a-w	c:\windows\system32\perfh00C.dat
+ 2009-01-10 10:08:18	472,162	----a-w	c:\windows\system32\perfh00C.dat
- 2009-01-07 12:24:41	20,044	-c--a-w	c:\windows\system32\Restore\rstrlog.dat
+ 2009-01-09 19:14:33	2,970,792	-c--a-w	c:\windows\system32\Restore\rstrlog.dat
+ 2000-07-15 00:00:00	148,480	----a-w	c:\windows\system32\TLBINF32.DLL
- 2001-08-23 15:47:20	8,192	----a-w	c:\windows\system32\tsbyuv.dll
+ 2001-08-23 16:47:20	8,192	----a-w	c:\windows\system32\tsbyuv.dll
- 2008-04-14 02:33:48	54,784	----a-w	c:\windows\system32\vfwwdm32.dll
+ 2008-04-14 03:33:48	54,784	----a-w	c:\windows\system32\vfwwdm32.dll
+ 2007-10-21 17:51:58	323,624	----a-w	c:\windows\system32\wiaaut.dll
.
-- Instantané actualisé --
.
(((((((((((((((((((((((((((((((((   Points de chargement Reg   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{a8f9752d-e2b8-4e7a-86b5-499f4330e2fe}"= "c:\program files\Eazel-FR\tbEaze.dll" [2008-11-23 1784856]

[HKEY_CLASSES_ROOT\clsid\{a8f9752d-e2b8-4e7a-86b5-499f4330e2fe}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a8f9752d-e2b8-4e7a-86b5-499f4330e2fe}]
2008-11-23 23:03	1784856	--a------	c:\program files\Eazel-FR\tbEaze.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{a8f9752d-e2b8-4e7a-86b5-499f4330e2fe}"= "c:\program files\Eazel-FR\tbEaze.dll" [2008-11-23 1784856]

[HKEY_CLASSES_ROOT\clsid\{a8f9752d-e2b8-4e7a-86b5-499f4330e2fe}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{A8F9752D-E2B8-4E7A-86B5-499F4330E2FE}"= "c:\program files\Eazel-FR\tbEaze.dll" [2008-11-23 1784856]

[HKEY_CLASSES_ROOT\clsid\{a8f9752d-e2b8-4e7a-86b5-499f4330e2fe}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
"EPSON Stylus DX4800 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIADE.EXE" [2005-02-02 98304]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Nero\Lib\NMBgMonitor.exe" [2007-09-20 202024]
"Google Update"="c:\documents and settings\Pascal C\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-06 133104]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-18 21633320]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-03 204288]
"ConquerCam"="c:\program files\ConquerCam\ConquerCam.exe" [2003-03-09 3452928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sunkist2k"="c:\program files\Multimedia Card Reader\shwicon2k.exe" [2005-02-25 131072]
"NeroFilterCheck"="c:\program files\Fichiers communs\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 1836328]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Lto Manager"="c:\program files\Quick GPS Connection Data Download Manager\DesktopLtoManager.exe" [2005-06-29 53248]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"00PCTFW"="c:\program files\PC Tools Firewall Plus\FirewallGUI.exe" [2008-12-11 2652056]
"LogitechCommunicationsManager"="c:\program files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 563984]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 2178832]
"VTPreset"="VTPreset.exe" [2004-02-24 c:\windows\system32\VTPreset.exe]
"nwiz"="nwiz.exe" [2008-10-07 c:\windows\system32\nwiz.exe]

c:\documents and settings\Pascal C\Menu D‚marrer\Programmes\D‚marrage\
Outil de notification Live Search.lnk - c:\documents and settings\Pascal C\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe [2008-12-18 143360]

c:\documents and settings\Pascal C\Menu D‚marrer\Programmes\D‚marrage\
Outil de notification Live Search.lnk - c:\documents and settings\Pascal C\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe [2008-12-18 143360]

c:\documents and settings\Pascal C\Menu D‚marrer\Programmes\D‚marrage\
Outil de notification Live Search.lnk - c:\documents and settings\Pascal C\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe [2008-12-18 143360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.JPEG"= JpegCode.dll
"VIDC.MJPG"= JpegCode.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XII.SP1\\Win32\\RpcDataSrv.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XII.SP1\\RpcSandraSrv.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\ConquerCam\\ConquerCam.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [2009-01-08 159600]
R3 pctplfw;pctplfw;c:\windows\system32\drivers\pctplfw.sys [2009-01-08 95640]
R4 GenPort;GenPort;c:\windows\system32\drivers\genport.sys [2008-12-16 4832]
R4 MapMem;MapMem;c:\windows\system32\drivers\MAPMEM.SYS [2008-12-16 6816]
R4 NTRemap;NTRemap;c:\windows\system32\drivers\NTREMAP.SYS [2008-12-16 6336]
R4 PCTAppEvent;PCTAppEvent Driver;c:\windows\system32\drivers\PCTAppEvent.sys [2009-01-08 73840]
R4 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2008-12-04 226640]
S1 aswSP;avast! Self Protection; [x]
S3 CoachVid;CoachVid;c:\windows\system32\drivers\CoachVid.sys [2009-01-09 45280]
S3 cusbohcn;cusbohcn;\??\c:\docume~1\PASCAL~1\LOCALS~1\Temp\cusbohcn.sys --> c:\docume~1\PASCAL~1\LOCALS~1\Temp\cusbohcn.sys [?]
S3 hcw95bda;Hauppauge MOD7700 Tuner Driver;c:\windows\system32\drivers\hcw95bda.sys [2008-01-29 467456]
S3 hcw95rc;Hauppauge MOD7700 IR Driver;c:\windows\system32\drivers\hcw95rc.sys [2008-01-29 15488]
S3 KS-959;Kingsun KS-959 USB Infrared Adapter;c:\windows\system32\drivers\KS-959.sys [2005-10-20 19034]
S3 TPP200;USB Storage Adapter V2 (TPP);c:\windows\system32\drivers\tpp200.sys [2007-09-05 35541]
S4 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys --> c:\windows\system32\DRIVERS\aswFsBlk.sys [?]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ee5aa206-7aa4-11dd-bc4c-0013d3a9fa58}]
\Shell\AutoRun\command - M:\InstallTomTomHOME.exe
.
Contenu du dossier 'Tâches planifiées'

2008-11-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 16:57]

2009-01-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3997960634-2553511711-1556241692-1007.job
- c:\documents and settings\Pascal C\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-06 15:06]
.
- - - - ORPHELINS SUPPRIMES - - - -

HKCU-Run-wLite - c:\program files\wLite\wLite.exe
HKCU-RunOnce-gi170593714 - c:\docume~1\PASCAL~1\LOCALS~1\Temp\36V4PMAT\implus_5_42_ppc\Resume.exe


.
------- Examen supplémentaire -------
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2095689
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://ads.eorezo.com/cgi-bin/advert/getads.cgi?x_format=redirect&x_dp_id=9
uInternet Connection Wizard,ShellNext = iexplore
IE: Add to Windows &Live Favorites
FF - ProfilePath - c:\documents and settings\Pascal C\Application Data\Mozilla\Firefox\Profiles\3vsoci2q.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Live Search
FF - prefs.js: browser.startup.homepage - hxxp://fr.msn.com/
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?mkt=fr-FR&FORM=MIMWA5&q=
FF - component: c:\program files\Mozilla Firefox\extensions\{a8f9752d-e2b8-4e7a-86b5-499f4330e2fe}\components\FFAlert.dll
FF - plugin: c:\documents and settings\Pascal C\Application Data\Mozilla\Firefox\Profiles\3vsoci2q.default\extensions\{bb628310-0ab7-11db-9cd8-0800200c9a66}\plugins\nphardwaredetection.dll
FF - plugin: c:\documents and settings\Pascal C\Local Settings\Application Data\Google\Update\1.2.133.33\npGoogleOneClick7.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npagent.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-13 11:53:32
Windows 5.1.2600 Service Pack 3 NTFS

Recherche de processus cachés ...

Recherche d'éléments en démarrage automatique cachés ...

Recherche de fichiers cachés ...

Scan terminé avec succès
Fichiers cachés: 0

**************************************************************************
.
Heure de fin: 2009-01-13 11:55:52
ComboFix-quarantined-files.txt  2009-01-13 10:55:41
ComboFix2.txt  2009-01-08 10:56:59

Avant-CF: 101 531 799 552 octets libres
Après-CF: 101,512,769,536 octets libres

Current=3 Default=3 Failed=2 LastKnownGood=5 Sets=1,2,3,4,5
356	--- E O F ---	2009-01-09 19:51:20
0
jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 040
 
aucune infection bagle! tu as fais des choses avant?

ton antivirus marche? avast, ad aware? ....

c'est quoi les problèmes que tu rencontre exactement
0
pascal21850 Messages postés 5 Statut Membre
 
bonsoir et merci
entre temps j'ai passé un scan avec antivir qui m'avais trouvé lui plus de 110 infections diverses
donc tout est bien qui fini bien
qulles sont les précautions à prendre pour éviter d'être à nouveau infecté
je me débrouille bien sur excel avec les formules et le vba mais j'avoue que l'aspect "sécurité" du pc me laisse souvent sans ressource et je ne dois pas être le seul à la vue du succès du forum
0
jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 040
 
pour protéger gratos ton ordi

http://www.commentcamarche.net/telecharger/logiciel 4 securite

mettre un antivirus

ANTIVIR ou AVG8 ou (AVAST )
https://www.malekal.com/avira-free-security-antivirus-gratuit/ (merci Malekal)
-------------
des anti-espions :
MalwareByte's Anti-Malware + SPYBOT +/- si tea timer non active de spybot:
WINDOWS DEFENDER ou SPYWARE TERMINATOR

+
SPYWAREBLASTER pour immuniser le système contre vundo notamment mais en anglais (mais facile d'utilisation : il suffit de faire "update" pour mettre à jour tous les mois et ensuite" enable all protection" pour immuniser)...

Rq : spybot et ad-aware ont sorti de nouvelles versions cette année vérifiez que vous avez la dernière version
--------
un pare feu :
celui de (Windows) ou mieux Online armor ou KERIO ou JETICO ou ZONE ALARM (mettre que le parefeu gratuit) ou COMODO

http://www.commentcamarche.net/telecharger/telecharger 34055356 online armor personal firewall
https://www.01net.com/telecharger/windows/Securite/firewall/fiches/39911.html
https://forum.pcastuces.com/sujet.asp?f=25&s=35606
https://www.clubic.com/telecharger-fiche11071-sunbelt-personal-firewall-ex-kerio.html
https://manuelsdaide.com/contact/
http://www.open-files.com/forum/index.php?showtopic=29277
http://www.commentcamarche.net/telecharger/telecharger 157 zonealarm

-----------
CCLEANER pour effacer les traces de surf
---------
naviguer avec firefox ou safari ou opera et non internet explorer plus touché par les virus
http://www.mozilla-europe.org/fr/products/firefox/
0